CVE-2026-12542
Received Received - Intake

OS Command Injection in Foreman foreman-tail Utility

Vulnerability report for CVE-2026-12542, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
foreman foreman_tail *
red_hat foreman_tail to 6.19.5 (inc)
red_hat red_hat_satellite 6.19.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a command injection vulnerability in Foreman's foreman-tail utility. It occurs because the script uses the eval command unsafely, directly incorporating user input into a string that gets executed. Without proper sanitization or quoting, attackers can inject shell metacharacters like semicolons or pipes to run arbitrary system commands.

Detection Guidance

Check for the presence of the foreman-tail utility on your system. Look for suspicious command execution patterns in system logs, such as unexpected shell metacharacters (;, &, |) in arguments passed to foreman-tail. Review scripts or cron jobs that may call this utility.

Impact Analysis

An attacker could exploit this to bypass restricted shells and execute unauthorized commands on the Satellite server. This may lead to access to sensitive information, remote code execution, and lateral movement across managed infrastructure.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized command execution on systems handling sensitive data. A successful exploit may lead to access to sensitive information or remote code execution, which could result in data breaches or unauthorized access to protected health or personal data.

Mitigation Strategies

Update the Foreman package to the latest version as soon as possible. Refactor the foreman-tail script to remove the eval command and replace it with safer alternatives like shell array expansion or the find command. Implement strict input validation to restrict input to valid service names only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12542. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart